Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

Shellshock: Bash Bug Vs Heartbleed

Shellshock (Bash Bug) Vs HeartBleed

The 'Bash bug', an acronym for Bourne Again Shell also known as Shellshock, is located in the command-line shell used in many Linux and Unix operating systems, leaving websites and devices power by these operating systems open to attack.

These are almost 25 years old vulnerability and is related to the processing of what are known as environment variables in Bash, which provide a way to influence the behavior of software.

The Bash bug was discovered by the Linux expert St phane Chazelas, and is causing concern as the command-line interface is used by many popular tools to run those environment variables.

An attacker could exploit a machine running Bash by forcing it to set specially crafted environment variables. Then after which this can be further exploited to let them execute shell commands, which means that run programs on other's devices. That's endgame for the victims - their machines would in effect be in the control of the hacker.

At Red Hat the bug was first identified, which is an American company that provides open-source software.

Now, What the hell is Heartbleed?

The problem affects a piece of software called OpenSSL an open-source project. Websites can provide encrypted information to visitors with OpenSSL, so the data transferred (which includes usernames, cookies and passwords) are not visible by others while it goes from your computer to the website.

OpenSSL was developed by volunteers who were really talented, this was free of charge, to help the internet communities. OpenSSL's version 1.0.1 was released on 19th April 2012, which has a little bug that allows for a person (including a malicious hacker) to retrieve information on the memory of the web server and it doesn't leave a trace behind. This was an honest mistake which was introduced with a new feature implemented by a German programmer: Dr. Robin Seggelmann, who is known for contributing security code.

Heartbleed exploits a built-in feature of OpenSSL known as heartbeat. Whenever your device accesses a website, the website will respond back to let your device know that it is active and listening for your requests: This is the heartbeat. This call and response is done by data exchange. Normally whenever your device makes a request, the heartbeat only send back the amount of data your device sent. This is not the case for servers which are currently affected by this bug. The hacker's are able to make the request to the server and also request data from the server's memory the total data of the initial request which goes upto 65536 bytes.

Which one is Bigger Attack - Shellshock or Heartbleed?

According, to Security firm Rapid7 has rated the bug as 10 out of 10 for its severity, but "low" for complexity - with hackers able to exploit it using just three lines of code.

Unlike Heartbleed, Shellshock doesn't require users to rush from site to site changing their passwords but it does give hackers another method of attack that they could potentially use to take over computers or mobile devices.

If Heartbleed's effect is akin to unlocking everyone's front door simultaneously, sending people scrambling back home to turn the key (ie change their passwords) then Shell;shock is like giving thieves a new type of crowbar to break in to houses with - they're just as likely to use older methods, but it's still a blow for general security.

Is there anything that I can do to protect against it?

Yes, you can fix it. First, you have to scan your computer, find it and then fixed this severe vulnerability in your environment by using famous software provided by Rapid7 security firm. They explain to you how to detect if you are vulnerable. Discuss the best way to develop a strategy to secure your environment. All on your demand.

Post by Shashank Arora from electrotechguide

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.